Web Security / Sessions and logins
Lesson 15 of 27
Storing passwords
Never store passwords in plain text, or with fast hashes like MD5. Use a slow, salted password hash such as bcrypt, scrypt or Argon2.
Key points
- Salted and slow
- werkzeug's generate_password_hash does this
- Never email passwords
from werkzeug.security import generate_password_hash, check_password_hashQuiz · +10 XP
Which is right for storing passwords?
Log in to save progress and earn XP.